2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-14273MEDIUM5.3In SilverStripe assets 4.0, there is broken access control on files.
CVE-2019-14272MEDIUM5.4In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.
CVE-2019-16903MEDIUM5.3Platinum UPnP SDK 1.2.0 allows Directory Traversal in Core/PltHttpServer.cpp because it checks for /.. where it should b...
CVE-2019-16738MEDIUM5.3In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup...
CVE-2019-16892MEDIUM5.5In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the unco...
CVE-2019-16890MEDIUM5.4Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments.
CVE-2019-12709MEDIUM6.7A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 900...
CVE-2019-12672MEDIUM6.8A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical ac...
CVE-2019-12670MEDIUM6.7A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx G...
CVE-2019-12668MEDIUM4.8A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote at...
CVE-2019-12667MEDIUM4.8A vulnerability in the web framework code of Cisco IOS XE Software could allow an authenticated, remote attacker to cond...
CVE-2019-12666MEDIUM6.7A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform dire...
CVE-2019-12662MEDIUM6.7A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with vali...
CVE-2019-12661MEDIUM6.7A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authentic...
CVE-2019-12660MEDIUM5.5A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the ...
CVE-2019-4571MEDIUM5.4IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...
CVE-2019-12649MEDIUM6.7A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker ...
CVE-2019-6655MEDIUM5.3On versions 13.0.0-13.1.0.1, 12.1.0-12.1.4.1, 11.6.1-11.6.4, and 11.5.1-11.5.9, BIG-IP platforms where AVR, ASM, APM, PE...
CVE-2019-6654MEDIUM4.3On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails to perform Martian A...
CVE-2019-12245MEDIUM5.3SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An atta...
CVE-2019-12205MEDIUM6.1SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS.
CVE-2019-12203MEDIUM6.3SilverStripe through 4.3.3 allows session fixation in the "change password" form.
CVE-2019-6653MEDIUM5.4There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 syst...
CVE-2019-6652MEDIUM6.5In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Laye...
CVE-2019-6651MEDIUM5.3In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now